Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Test blanc

Total questions: 20

Worksheet time: 15mins

Name
Class
Date
1.

Cybersecurity activities should be coordinated by:

a)

Representatives from different parts of the organization with relevant roles and job functions

b)

The chief information security officer

c)

The cybersecurity program manager

2.

“Level of risk” is defined with the following statement

a)

Magnitude of a risk expressed in terms of the potential vulnerabilities and the threats that they possess

b)

List of risks with value levels assigned

c)

Magnitude of a risk expressed in terms of the combination of consequences and their likelihood

3.

The risk that remains after the implementation of controls aiming to reduce the inherent risk is defined as

a)

Treated risk

b)

Residual risk

c)

Avoided risk

4.

Monitoring systems which do not respond to anything against incoming packets found within the Darknet IP domains refers to

a)

Black hole monitoring

b)

White hole monitoring

c)

Gray hole monitoring

5.

Please determine the correct definition of threats in the cyberspace

a)

Potential cause of an unwanted incident, which may result in harm to a system, individual or organization

b)

Weakness of an asset or control that can be exploited

c)

Effect of uncertainty on objectives

6.

The expression of the intent of the organization to treat the risks identified and/or to comply with requirements of organizational security is the objective of

a)

Cybersecurity program

b)

Information security program

c)

Cyberspace program

7.

Which of the risk treatment options the organization is adopting, in the scenario when it has recently conducted a risk assessment of their IT systems and decided to cancel the e-commerce activity to eliminate the risk of an accidental phishing threat?

a)

Risk Modification

b)

Risk Elimination

c)

Risk Avoidance

8.

which of the following is a type of malware?

a)

Worm

b)

Ransomwar

c)

Virus

d)

DoS

e)

DDoS

9.

Which of the risk treatment options the organization is adopting, in the scenario when it has recently conducted a risk assessment of their IT systems and decided to implement a new data loss prevention system to reduce the likelihood of an accidental data breach?

a)

Risk Modification

b)

Risk Retention

c)

Risk Avoidance

10.

Individual or organization having a right, share, claim or interest in a system or in its possession of characteristics that meet their needs and expectations is the definition of:

a)

Stakeholder

b)

Consumers

c)

Providers

11.

Which tools are more suitable to control network services accessing the user systems?

a)

Personal firewalls

b)

HIDS

c)

Personal firewalls and HIDs

12.

Establishing a system for information sharing and coordination:

a)

Helps in preparing and responding to legal and regulatory requirements

b)

Helps in preparing and responding to cybersecurity events and incidents

c)

Helps in preparing and responding to customer complaints and requests

13.

Visibility of changes and the emerging security incident taking place without the need for the operators to read the details of each event as it emerges can be improved through:

a)

Data standardization

b)

Data visualization

c)

Telephone communication

14.

A process that defines the dangers that threat an organization refers to:

a)

Information security

b)

Disaster recovery

c)

Business continuity

15.

Anything that has a value to an individual, an organisation or a government.

a)

information

b)

information asset

c)

asset

16.

Which of the following should be involved in the cybersecurity program?

a)

Business functions

b)

IT related functions

c)

Business and IT-related functions

17.

Why is it important for the cybersecurity program manager to understand the business process of the organization?

a)

It is the conduct of the process that exposes the organization to numerous security risks

b)

The cybersecurity program manager’s responsibilities should focus on the understanding of ICT related process only

c)

The risk manager should analyze and understand the nature of these processes

18.

Which of the following controls aims to discourage the appearance of the problems?

a)

Detective control

b)

Preventive Control

c)

Corrective Control

19.

While auditing the security level of an organization, we noticed that all employees' data are unencrypted. What's the possible threat in this case?

a)

Virus

b)

Loss of information

c)

information theft

20.

Which of the following does the process of risk treatment involve?

a)

Selecting one or more options for modifying risks, and implementing these options

b)

Selecting one or more options for eliminating risks, and implementing these options

c)

Selecting one or more options for analyzing risks, and implementing these options